Temat: Transmission i spam w logach
Witam, otóż jest taki problem nad którym sobie siedzę przy herbatce i rozkminiam. Log jest cały "zapchany" przez transmission errorami.
Port jest otwarty (wg tutoriala), z ciekawości też przekierowałem.
Wed Feb 19 00:40:46 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 28 to 2001:0:5ef5:79fb:1c28:3434:d1f0:2465, port 10146 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:40:46 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 28 to 2001:0:5ef5:79fb:1c28:3434:d1f0:2465, port 10146 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:41:11 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 22 to 2001:0:5ef5:79fb:340b:3906:a9ef:730, port 44192 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:41:11 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 22 to 2001:0:5ef5:79fb:340b:3906:a9ef:730, port 44192 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:41:57 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 21 to 2001:0:9d38:6ab8:4f2:3915:4109:e44b, port 33377 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:41:57 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 21 to 2001:0:9d38:6ab8:4f2:3915:4109:e44b, port 33377 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:41:57 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 21 to 2001:0:9d38:6ab8:34a3:ae27:b16f:d47b, port 50802 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:41:57 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 21 to 2001:0:9d38:6ab8:34a3:ae27:b16f:d47b, port 50802 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:41:57 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 21 to 2001:0:5ef5:79fb:1c28:3434:d1f0:2465, port 10146 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:41:57 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 21 to 2001:0:5ef5:79fb:1c28:3434:d1f0:2465, port 10146 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:42:18 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 35 to 2001:0:9d38:6abd:2cdc:234f:ace8:d160, port 40000 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:42:18 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 35 to 2001:0:9d38:6abd:2cdc:234f:ace8:d160, port 40000 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:42:23 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 35 to 2001:0:5ef5:79fd:819:2289:a104:5ae5, port 12578 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:42:23 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 35 to 2001:0:5ef5:79fd:819:2289:a104:5ae5, port 12578 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:42:24 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 35 to 2001:0:5ef5:79fb:340b:3906:a9ef:730, port 44192 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:42:24 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 35 to 2001:0:5ef5:79fb:340b:3906:a9ef:730, port 44192 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:42:38 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 25 to 2001:0:5ef5:79fb:1c28:3434:d1f0:2465, port 10146 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:42:38 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 25 to 2001:0:5ef5:79fb:1c28:3434:d1f0:2465, port 10146 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:43:22 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 29 to 2001:0:9d38:6ab8:4f2:3915:4109:e44b, port 33377 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:43:22 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 29 to 2001:0:9d38:6ab8:4f2:3915:4109:e44b, port 33377 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:43:41 2014 daemon.err transmission-daemon[999]: Gravity (2013)[1080p.BRRip.x264.DTS.AC3][Dual Audio][Lektor i Napisy PL] Piece 67, which was just downloaded, failed its checksum test (torrent.c:3251)
Wed Feb 19 00:43:46 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 21 to 2001:0:5ef5:79fb:340b:3906:a9ef:730, port 44192 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:43:46 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 21 to 2001:0:5ef5:79fb:340b:3906:a9ef:730, port 44192 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:44:00 2014 kern.notice kernel: [ 316.384000] EXT4-fs (sda3): error count: 1
Wed Feb 19 00:44:00 2014 kern.notice kernel: [ 316.388000] EXT4-fs (sda3): initial error at 16: ext4_lookup:1437: inode 47
Wed Feb 19 00:44:00 2014 kern.notice kernel: [ 316.392000] EXT4-fs (sda3): last error at 16: ext4_lookup:1437: inode 47
Wed Feb 19 00:44:12 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 28 to 2001:0:5ef5:79fb:1c28:3434:d1f0:2465, port 10146 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:44:12 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 28 to 2001:0:5ef5:79fb:1c28:3434:d1f0:2465, port 10146 (errno 1 - Operation not permitted) (net.c:288)Router:
root@OpenWrt:~# cat /etc/config/firewall
config redirect
option target 'DNAT'
option src 'wan'
option dest 'lan'
option proto 'tcp'
option dest_ip '192.168.2.1'
option dest_port '80'
option name 'GATEWAY'
option src_dport '50'
config redirect
option target 'DNAT'
option src 'wan'
option dest 'lan'
option proto 'tcp'
option src_dport '52'
option dest_ip '192.168.2.1'
option dest_port '22'
option name 'ssh1'
config redirect
option target 'DNAT'
option src 'wan'
option dest 'lan'
option proto 'tcp'
option dest_ip '192.168.2.2'
option dest_port '80'
option name 'WEBSERVER'
option src_dport '60'
config redirect
option target 'DNAT'
option src 'wan'
option dest 'lan'
option proto 'tcp udp'
option dest_ip '192.168.2.2'
option dest_port '21'
option name 'FTP'
option src_dport '61'
config redirect
option target 'DNAT'
option src 'wan'
option dest 'lan'
option proto 'tcp'
option dest_ip '192.168.2.2'
option dest_port '22'
option src_dport '62'
option name 'ssh2'
config redirect
option target 'DNAT'
option src 'wan'
option dest 'lan'
option proto 'tcp udp'
option dest_ip '192.168.2.2'
option dest_port '9091'
option name 'Transmission'
option src_dport '65'
config defaults
option syn_flood '1'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
config zone
option name 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
option network 'lan'
config zone
option name 'wan'
option output 'ACCEPT'
option masq '1'
option mtu_fix '1'
option network 'wan'
option forward 'REJECT'
option input 'REJECT'
config forwarding
option src 'lan'
option dest 'wan'
config rule
option name 'Allow-DHCP-Renew'
option src 'wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option name 'Allow-Ping'
option src 'wan'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-DHCPv6'
option src 'wan'
option proto 'udp'
option src_ip 'fe80::/10'
option src_port '547'
option dest_ip 'fe80::/10'
option dest_port '546'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Input'
option src 'wan'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Forward'
option src 'wan'
option dest '*'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config include
option path '/etc/firewall.user'
config rule
option name 'transmission'
option src 'wan'
option target 'ACCEPT'
option proto 'tcp'
option dest_port '51413'
config redirect
option target 'DNAT'
option src 'wan'
option dest 'lan'
option proto 'tcp udp'
option src_dport '51413'
option dest_ip '192.168.2.2'
option dest_port '51413'
option name 'Transmission_zew_port'serwer:
root@OpenWrt:~# cat /etc/config/firewall
config defaults
option syn_flood '1'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
config zone
option name 'lan'
list network 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
config zone
option name 'wan'
list network 'wan'
list network 'wan6'
option output 'ACCEPT'
option masq '1'
option mtu_fix '1'
option input 'ACCEPT'
option forward 'ACCEPT'
config forwarding
option src 'lan'
option dest 'wan'
config rule
option name 'Allow-DHCP-Renew'
option src 'wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option name 'Allow-Ping'
option src 'wan'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-DHCPv6'
option src 'wan'
option proto 'udp'
option src_ip 'fe80::/10'
option src_port '547'
option dest_ip 'fe80::/10'
option dest_port '546'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Input'
option src 'wan'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Forward'
option src 'wan'
option dest '*'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config include
option path '/etc/firewall.user'
config rule
option name 'transmission'
option target 'ACCEPT'
option dest_port '51413'
option proto 'all'
option src '*'
config rule
option enabled '1'
option target 'ACCEPT'
option proto 'tcp udp'
option dest_port '55'
option name 'transmission2'
option src 'lan'